Accepted mooix 0.4.1.12.1 (i386 source)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Tue, 11 Jun 2002 11:45:03 -0400
Source: mooix
Binary: mooix
Architecture: source i386
Version: 0.4.1.12.1
Distribution: unstable
Urgency: low
Maintainer: Joey Hess <joeyh@debian.org>
Changed-By: Joey Hess <joeyh@debian.org>
Description:
mooix - Unix is the moo.
Changes:
mooix (0.4.1.12.1) unstable; urgency=low
.
* Audited all stackless methods...
* Reworked destroy again, closing additional holes that let a programmer
call a guest's logout method successfully, and that let a programmer spoof
the mooadmin's recycle_verb. The new destroy uses the objstack correctly
and is safe from these types of spoofs.
* Made thinglist->init not be raceable to set unprotected &etc fields.
* Don't let just any programmer call ssh->setkey and pass it a key. Instead,
introduce a sshkey field of avatars; setkey simply validates and copies
that key into the ssh object. Changed setting of ssh keys to be done by
saying: my sshkey is "blahblahblah". As a bonus, multiple keys can now be
set, and keys can be unset, too.
* safedeletefield calls _validate methods too, and its return value is now
similar to safesetfield's.
* ttysession page need not be stackless if the pagefile is created on init.
* Make ttysession page and write (and log session write) read all parameters
before locking anything, so an attacker cannot call them and block sending
params to hang the session. Added a getallvals() to the C binding to
facilitate this.
* Made the single session prompt method not stackless, as there is no sane
way to check its callers. Instead, make the parser know about single
sessions, and abort after one line is read from them.
* Fixed ttysession's write method's handling of very long unwrappable lines.
* Fixed log session's handling of writes of more than one line at a time;
prefix each line with its own timestamp.
* Don't log self-emotes.
Files:
522dd481cd5b84dac42db7aae95bebf2 542 misc optional mooix_0.4.1.12.1.dsc
d86215f430523a0e3f3a9c51e6079be2 333307 misc optional mooix_0.4.1.12.1.tar.gz
d8d6768b6206c14a7255d44c2c082b4f 304026 misc optional mooix_0.4.1.12.1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
iD8DBQE9Bpae2tp5zXiKP0wRAq9sAKC1BkepJQc+ZqfPckqMsvsJshaAIACgpWYo
DHskyrpde+Dpyp/ajtmh0V8=
=lBH0
-----END PGP SIGNATURE-----
Accepted:
mooix_0.4.1.12.1.dsc
to pool/main/m/mooix/mooix_0.4.1.12.1.dsc
mooix_0.4.1.12.1.tar.gz
to pool/main/m/mooix/mooix_0.4.1.12.1.tar.gz
mooix_0.4.1.12.1_i386.deb
to pool/main/m/mooix/mooix_0.4.1.12.1_i386.deb
--
To UNSUBSCRIBE, email to debian-devel-changes-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply to: